« All threats

APT groupMITRE G1057

ShinyHunters

Also known as: bling libra, unc6240

Profile

ShinyHunters (also tracked as UNC6240) is a data-theft and extortion group whose current activity has been documented since 2025 and which, according to the FBI, has breached more than 140 organisations and collected at least $70 million in payments. Its core method is large-scale data theft: it abuses corporate SSO accounts, third-party suppliers and cloud SaaS platforms (Salesforce, Snowflake), and since 2026 has been mass-exploiting a zero-day in Oracle PeopleSoft (CVE-2026-35273), bypassing WAFs through URL encoding to drop web shells. Victims span education, technology, healthcare, agriculture, transport and logistics, finance, telecoms and government, with notable cases including the theft of 2-3 TB of data from the FBI's job application portal (FBIJobs.gov), which was also defaced, and a breach at Dutch telecoms operator Odido. A distinguishing trait is its strong public messaging: it denies that its activity amounts to extortion and framed the FBI incident as a 'marketing campaign'. Despite the September 2026 arrest in the Netherlands of an alleged 24-year-old leader, the group remains active and denied any link to that individual.

Active since: 2025

Initial access

Tools

Web shells, MeshCentral remote management agent (MeshAgent), Neo-reGeorg (tunnelling proxy), SIDEEYE, Ple64.exe

What defenders should watch

Victims in the last 90 days39

Most affected countries

  1. United States21
  2. Germany1
  3. France1
  4. United Kingdom1
  5. Israel1
  6. Sweden1

Most affected sectors

  1. Technology11
  2. Other10
  3. Pharma & chemicals7
  4. Healthcare3
  5. Finance & insurance2
  6. Professional services2
  7. Media & entertainment1
  8. Manufacturing1

Vulnerabilities attributed

CVESeverityEPSSActive exploitation
CVE-2026-35273Critical (9.8)9.4%⚠ Active exploitation

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. User Account Management (13 techniques covered)
  2. User Training (12 techniques covered)
  3. Multi-factor Authentication (8 techniques covered)
  4. Audit (8 techniques covered)
  5. Privileged Account Management (7 techniques covered)
  6. Password Policies (6 techniques covered)
  7. Account Use Policies (5 techniques covered)
  8. Filter Network Traffic (5 techniques covered)

MITRE ATT&CK techniques

Recent victims

OrganisationCountrySectorClaimedStatus
🔒 Comunicado de grupo criminal—Other9/30/2026◌ Claimed (unverified)
🔒 Entidad desconocida—Other9/24/2026◌ Claimed (unverified)
🔒 Entidad no identificada—Other9/23/2026◌ Claimed (unverified)
Fresenius Medical CareGermanyHealthcare9/23/2026◌ Claimed (unverified)
🔒 Entidad no identificada—Other9/22/2026◌ Claimed (unverified)
🔒 Organización sin identificar—Other9/20/2026◌ Claimed (unverified)
🔒 Organización—Other9/17/2026◌ Claimed (unverified)
Kimberly-ClarkUnited StatesManufacturing9/13/2026◌ Claimed (unverified)
State of Florida DMVUnited StatesGovernment9/7/2026◌ Claimed (unverified)
Medela—Healthcare9/7/2026◌ Claimed (unverified)
🔒 Servicio de datos—Other9/4/2026◌ Claimed (unverified)
NeoGen CorporationUnited StatesTechnology9/3/2026◌ Claimed (unverified)
Neogen CorporationUnited StatesOther8/29/2026◌ Claimed (unverified)
McKesson CorporationUnited StatesPharma & chemicals8/29/2026◌ Claimed (unverified)
Elekta ABSwedenTechnology8/28/2026◌ Claimed (unverified)
Jack Henry & AssociatesUnited StatesFinance & insurance8/28/2026◌ Claimed (unverified)
CyrusOneUnited StatesTechnology8/23/2026◌ Claimed (unverified)
ReliaQuest, LLCUnited StatesTechnology8/23/2026◌ Claimed (unverified)
NovoCure LimitedUnited KingdomPharma & chemicals8/22/2026◌ Claimed (unverified)
BOK FinancialUnited StatesFinance & insurance8/22/2026◌ Claimed (unverified)
🔒 Entidad no identificada—Other8/20/2026◌ Claimed (unverified)
Logitech / Streamlabs—Technology8/18/2026◌ Claimed (unverified)
Brinks HomeUnited StatesTechnology8/18/2026◌ Claimed (unverified)
Alcon, Inc.United StatesPharma & chemicals8/18/2026◌ Claimed (unverified)
Lumenis Ltd.IsraelPharma & chemicals8/18/2026◌ Claimed (unverified)

Sources analysed

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.